aci_epg_segment
Resolve an ACI EPG's bridge domain, VRF, and contract filters by name. Identifies unenforced VRFs and unformed relations, listing findings with causes and actions for troubleshooting.
Instructions
[READ] An ACI EPG's segment: bridge domain, VRF and contracts, by name.
Follows EPG → BD → VRF through the relations APIC resolved (cross-tenant
links into 'common' included) and expands the contracts the EPG provides
and consumes down to filter entries. Use it when you know the EPG but not
an endpoint in it.
A relation that is not 'formed' is reported as a finding with its state; a
read that failed is null with an entry in 'errors' (not empty — say it was
not read). An unenforced VRF means contracts do not restrict traffic in it.
'notChecked' lists what is not evaluated (vzAny, taboo, imported
contracts, preferred-group peers, service graphs).
Args:
tenant: Tenant name (e.g. 'tenant-A').
app: Application profile name.
epg: EPG name.
target: Target name from config (must be 'platform: aci').
Returns dict: {epg, bd, vrf, contracts:{contracts, returned, limit,
truncated, filters, filtersTruncated, complete}, segmentResolved,
notChecked,
findings:[{rank, severity, signal, cause, action}], errors}.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| app | Yes | ||
| epg | Yes | ||
| target | No | ||
| tenant | Yes |